Resolved
We're closing this incident. On April 30, 2026 an attacker published malicious versions of intercom-client (v7.0.4) and intercom-php (v5.0.2). Both were removed from distribution within hours of discovery. No evidence of unauthorized access to customer data or Intercom accounts was found.
If you installed intercom-client@7.0.4 or intercom-php@5.0.2 on April 30 and haven't already done so, we recommend rotating any credentials configured in that environment. All other versions of both packages are safe.
We kept the incident open out of an abundance of caution while we completed credential rotation, hardened our infrastructure, and monitored closely for any follow-on activity. We're now satisfied it's fully remediated.